> For the complete documentation index, see [llms.txt](https://docs.scepman.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.scepman.com/de/zertifikatsverwaltung/static-certificates/addigy.md).

# Addigy

Stellen Sie Zertifikate in Addigy aus, indem Sie SCEPman als externe CA verbinden. Geräte können Zertifikate über SCEPmans statische Schnittstelle und ein hinterlegtes Challenge-Passwort erhalten.

SCEPman kann integriert werden mit [Addigy](https://addigy.com/) als externe Zertifizierungsstelle (CA) mithilfe von SCEPmans statischer Schnittstelle. Mit einem konfigurierten Challenge-Passwort können registrierte Geräte Zertifikate anfordern und erhalten.

Für allgemeinere Informationen zu anderen MDM-Lösungen und zur SCEPman-Integration besuchen Sie bitte [hier](/de/zertifikatsverwaltung/static-certificates.md).

## Addigy-Integration aktivieren

Die Integration von SCEPman kann einfach über die folgenden Umgebungsvariablen im SCEPman App Service aktiviert werden:

{% hint style="info" %}
Sie können zwischen dem SCEPman App Service und dem Certificate Master unterscheiden, indem Sie nach dem App Service **ohne** dem "-cm" in seinem Namen
{% endhint %}

|                                                                                                Einstellung                                                                                               | Beschreibung                                                                                                                                                                                                                                                                                                                                            |                           Wert                           |
| :------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------: | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | :------------------------------------------------------: |
|                        [AppConfig:StaticValidation:Enabled](/de/scepman-konfiguration/application-settings/scep-endpoints/static-validation.md#appconfig-staticvalidation-enabled)                       | Validierung von Drittanbietern aktivieren                                                                                                                                                                                                                                                                                                               | ***true*** zum Aktivieren, ***falsch*** zum Deaktivieren |
|                [AppConfig:StaticValidation:RequestPassword](/de/scepman-konfiguration/application-settings/scep-endpoints/static-validation.md#appconfig-staticvalidation-requestpassword)               | <p>Zertifikatsignierungsanforderungen, die zur Signierung an SCEPman gesendet werden, werden mit diesem sicheren statischen Passwort authentifiziert<br><br><strong>Empfehlung</strong>: Speichern Sie dieses Geheimnis in <a href="/de/scepman-konfiguration/application-settings.md#secure-configuration-in-azure-key-vault">Azure Key Vault</a>.</p> |        *generieren Sie ein 32-stelliges Passwort*        |
|       [AppConfig:StaticValidation:ValidityPeriodDays](/de/scepman-konfiguration/application-settings/scep-endpoints/static-validation.md#appconfig-staticvalidation-validityperioddays) (optional)       | Tage, für die über Addigy ausgestellte Zertifikate gültig sind                                                                                                                                                                                                                                                                                          |                            365                           |
| [AppConfig:StaticValidation:EnableCertificateStorage](/de/scepman-konfiguration/application-settings/scep-endpoints/static-validation.md#appconfig-staticvalidation-enablecertificatestorage) (optional) | Speichern Sie angeforderte Zertifikate im Storage Account, um sie in SCEPman Certificate Master anzuzeigen                                                                                                                                                                                                                                              | ***true*** zum Aktivieren, ***falsch** zum Deaktivieren* |

{% hint style="warning" %}
Nachdem Sie SCEPman-Konfigurationsparameter hinzugefügt oder bearbeitet haben, müssen Sie den App Service neu starten.
{% endhint %}

## Addigy-Konfiguration

### SCEPman-Root-Zertifikat

Als ersten Schritt muss das SCEPman-Stammzertifikat bereitgestellt werden. Laden Sie dazu das RootCA-Zertifikat über die SCEPman-Website herunter:

![SCEPman-Website](https://2075553437-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-LoGejQeUQcw7lqnQ3WX%2Fuploads%2Fgit-blob-9170eb0435726398eb43f6fac8abd0d5f35e8cc4%2FSCEPmanHomePage%20\(1\)%20\(1\)%20\(1\)%20\(1\)%20\(1\)%20\(1\)%20\(1\)%20\(1\)%20\(1\)%20\(1\)%20\(1\)%20\(1\)%20\(2\)%20\(1\)%20\(2\).png?alt=media)

Konvertieren Sie nun das .cer-Stammzertifikat in das PEM-Format, um es auf Addigy hochzuladen. Dafür können Sie den folgenden OpenSSL-Befehl verwenden:

```
openssl x509 -inform der -in scepman-root.cer -out SCEPman-Root-Certificate.pem
```

Navigieren Sie in Addigy zu **Profile** und erstellen Sie ein neues MDM-Profil, wählen Sie **Zertifikate - (PKCS12)** als Profiltyp, um das SCEPman-RootCA hochzuladen, und laden Sie die PEM-formatierte Datei hoch.

<figure><img src="https://2075553437-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-LoGejQeUQcw7lqnQ3WX%2Fuploads%2FRAcvBOaWt0V089lb96aP%2Fimage.png?alt=media&amp;token=187ce30f-6f6f-4ae0-9b97-cb21713b585b" alt=""><figcaption></figcaption></figure>

### SCEP-Profil

Der zweite Schritt besteht darin, ein neues **SCEP-Profil** für die Bereitstellung von Gerätezertifikaten wie unten zu erstellen:

* **Nutzlastname:** Wählen Sie einen Namen für das Profil; dieser wird auf dem Client als Zertifikatsprofil angezeigt.
* **URL**: Der statische SCEP-Endpunkt von SCEPman, den Sie in einem vorherigen Schritt konfiguriert haben; Sie können ihn von der SCEPman-Startseite abrufen, siehe unten:

<figure><img src="https://2075553437-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-LoGejQeUQcw7lqnQ3WX%2Fuploads%2FZHNTUBLUO3y3BHH0R37X%2Fimage.png?alt=media&amp;token=a4b0d735-167d-41ea-aa32-2c445325a42b" alt=""><figcaption></figcaption></figure>

* **Challenge**: Wird benötigt, um CSR-Anfragen zu authentifizieren, die an SCEPmans statische SCEP-Schnittstelle gesendet werden. Es muss übereinstimmen mit dem [Wert](/de/scepman-konfiguration/application-settings/scep-endpoints/static-validation.md#appconfig-staticvalidation-requestpassword) der Einstellung *AppConfig:StaticValidation:RequestPassword* die Sie zuvor konfiguriert haben.
* Aktivieren Sie die **"Proxy SCEP Requests"** Option
* Wählen Sie für "Signing & Encryption" **Schlüsselverwendung**
* Füllen Sie den Rest wie in den folgenden Screenshots gezeigt aus

<figure><img src="https://2075553437-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-LoGejQeUQcw7lqnQ3WX%2Fuploads%2FIRC4uYWrileRNfteYpIV%2Fimage.png?alt=media&amp;token=4b0f0c81-2c16-4b69-9143-5aed25a87477" alt=""><figcaption></figcaption></figure>

<figure><img src="https://2075553437-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-LoGejQeUQcw7lqnQ3WX%2Fuploads%2FpKRdVeJYOPm1TUd6c2AY%2Fimage.png?alt=media&amp;token=3b474821-967f-4b6e-968e-812a66d9edde" alt=""><figcaption></figcaption></figure>

Nachdem Sie sowohl das Root-CA- als auch das Gerätezertifikatsprofil erfolgreich erstellt haben, wenden Sie sie auf Ihre Richtlinie an, um die Konfiguration auf den zugewiesenen Geräten bereitzustellen.

Für weitere Informationen besuchen Sie bitte [Addigys Dokumentation.](https://support.addigy.com/hc/en-us/articles/4403542430739-Deploying-Certificates)


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.scepman.com/de/zertifikatsverwaltung/static-certificates/addigy.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
